ADR 0099: a step that runs once names what it reads; issues 077 and 078 resolved; designs 08 and 20 amended

This commit is contained in:
2026-09-21 23:33:47 +02:00
parent c2a81cbb20
commit 0e0f0298c6
8 changed files with 146 additions and 7 deletions
+4 -3
View File
@@ -9,6 +9,7 @@ code:
- mesh-host internal/apply (the service that reflects a rule set)
updated: 2026-09-21
decisions:
- 02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md
- 02-DECISIONS/0098-a-fact-a-provider-makes-at-first-start-is-fetched-from-it.md
- 02-DECISIONS/0005-the-node-host.md
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
@@ -564,9 +565,9 @@ The mesh mints the authority's password and nothing else of its: a root certific
are things only the authority can make, and a served fact written in a manifest cannot carry what
does not exist until the authority has run. So the authority serves its root at a path beside its
ACME directory, and the proxy that requires it fetches that root over the mesh network in a
run-once step before it starts. The step is run once per declaration: a root that changes
after first start is fetched again only when the declaration changes
([issue 077](../../04-ISSUES/077-a-fact-fetched-at-first-start-is-fetched-once/00-report.md)).
run-once step before it starts. The step names the binding it reads and the proxy names the
step, so when the authority moves the root is fetched again and the proxy is recreated with it
([ADR 0099](../../02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md)).
*How it is checked:* the route-forwarding bed installs the authority, the proxy and a consumer
from the catalogue and asserts the routed name is served.